ransomware
Credible
South Africa (ZA)
hospitality
Singita listed by the DragonForce ransomware group
Singita
CompanySingita
Domainsingita.com
CountrySouth Africa (ZA)
Sectorhospitality
Breach date2026-04-02
People affectedNot disclosed
Ransomware groupdragonforce
Data typesguest data, reservation records, corporate information
Overview
The DragonForce ransomware group has listed Singita, a South African luxury safari and conservation hospitality company operating lodges and camps across Africa, on its leak site. The listing appeared on 2 April 2026.
What was published
The group claims to have exfiltrated data from the company. Luxury hospitality operations hold guest profiles, reservation records and corporate information, which are the likely contents of any exfiltration.
Risks for affected individuals
- Guests' personal data may be exposed.
- Reservation and payment records could enable fraud.
- Employees' information may be included.
What remains unknown
- The volume of records involved.
- Whether the data has been published.
- The response status of the company.
What affected people should do
Guests should monitor payment activity and be cautious of unsolicited messages referencing the company. Singita should notify affected guests and staff, review compromised systems, and communicate the scope of the incident.

Sources
- http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/blog/?post_uuid=0e64a450-0c5f-43d6-911e-81456466f406